Manage API Keys
Use API keys to connect scripts, automations and compatible integrations to dopost.
Each key belongs to one workspace and grants only the permissions selected when it is created.
Before you start
API access is available on Pro and Agency plans.
Only workspace Owners and Admins can manage API keys.
Select the correct workspace before creating a key.
For AI clients that support dopost sign-in through OAuth, you can connect without creating an API key. See the MCP setup guide.
Create an API key
Select the workspace you want the integration to use.
Open Settings → API keys.
Select Generate Key.
Enter a name that identifies the integration.
Select the permissions it needs.
Select Generate.
Copy the key and store it securely.
The complete key is shown only once. After closing the dialog, you cannot retrieve it again.
Choose permissions
Permissions control which actions the integration can perform, such as reading accounts, publishing posts, accessing media or reading analytics.
Select only the permissions your integration needs. At least one permission must be selected.
Use View permissions on an existing key to check its access.
To use a different set of permissions, create a replacement key and update your integration.
Use the key
Enter the key in your integration’s API key field.
For direct API requests, send it in the x-api-key header:
x-api-key: YOUR_API_KEYSee the API getting started guide for request examples.
The key provides access to its own workspace. Create separate keys for integrations that need to work with different workspaces.
Temporarily disable a key
Open Settings → API keys and turn off the key’s switch.
Requests using that key will be rejected while it is disabled. Turn the switch on again to restore access.
Disabling a key does not delete it.
Delete a key
Open Settings → API keys.
Find the key and select its delete action.
Confirm deletion.
Deletion permanently revokes the key and cannot be undone. Any integration using it will need a replacement key.
Replace a lost or exposed key
Create a new key with the required permissions.
Update your integration to use it.
Delete the old key.
If a key was exposed, disable or delete it immediately.
Having trouble?
API keys are unavailable: check the plan and your workspace role.
You lost the complete key: create a replacement; existing keys cannot be revealed again.
Authentication fails: check that the key was copied correctly and remains active.
An action is forbidden: check the key’s permissions and the workspace’s API access.
Expected accounts or posts are missing: confirm that the key belongs to the correct workspace.